Courseiva

SCS-C03 · domain

Identity and Access Management

Practise AWS Certified Security - Specialty Identity and Access Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

21 questions5 easy7 medium9 hard

Focused practice

Practice Identity and Access Management questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Identity and Access Management

Identity and Access Management questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Identity and Access Management exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Identity and Access Management questions (21)

Click any question to see the full explanation, or start a practice session above.

1

A large enterprise wants to implement SAML 2.0-based federation to allow employees to access the AWS Management Console using their existing corporate credentials. Which TWO steps are required to establish this trust relationship and enable user access?

Hard
2

Which THREE actions are best practices for managing root user account security? (Select THREE)

Hard
3

A security engineer is using Service Control Policies (SCPs) to manage permissions across an AWS Organization. Which TWO statements accurately describe the behavior and limitations of SCPs?

Easy
4

A security engineer is troubleshooting an IAM policy evaluation issue where an explicit deny statement inside a permissions boundary is failing to restrict permissions as expected for a developer role. Which TWO factors must the engineer verify during the evaluation process?

Hard
5

Refer to the exhibit. An IAM user with the 'Finance' tag is trying to upload an object to the 'production-data' bucket. The upload is failing. What is the most likely cause?

Medium
6

A company is setting up SAML 2.0 federation to allow employees to log into the AWS Management Console using their corporate credentials. Which TWO components are required to establish this trust relationship in AWS?

Medium
7

A developer in Account A needs to use an AWS KMS customer managed key (CMK) located in Account B to encrypt data. Which TWO configuration steps are necessary to allow this cross-account access?

Hard
8

A company uses AWS Organizations with all features enabled. A security engineer has applied a Service Control Policy (SCP) at the Organizational Unit (OU) level that explicitly denies the 'iam:CreateUser' action. However, a specific IAM user in a member account within that OU has an administrator policy attached. What is the resulting behavior when this user attempts to create a new IAM user?

Medium
9

A company is using AWS IAM Identity Center (successor to AWS Single Sign-On) to manage access to their AWS accounts. They want to automate the process of adding and removing users based on their status in an external identity provider. Which protocol should they use?

Easy
10

A security engineer needs to prevent IAM users from disabling CloudTrail. Which policy element is most appropriate?

Hard
11

An auditor needs to verify which IAM policies are attached to a specific user. Which command provides this information?

Medium
12

A company is building a mobile application that requires users to authenticate before accessing private data stored in Amazon S3 and Amazon DynamoDB. Which THREE components or features of Amazon Cognito should be used to implement this securely?

Hard
13

A company wants to identify any S3 buckets or IAM roles in their AWS account that are accessible by external AWS accounts or public users. Which AWS service provides this functionality by analyzing resource-based policies?

Easy
14

Which IAM configuration helps prevent the 'confused deputy' problem when accessing cross-account resources?

Medium
15

A security engineer is tasked with granting a developer in Account A access to an Amazon S3 bucket located in Account B. The developer needs to perform PutObject and GetObject operations. According to security best practices for cross-account access, which configuration provides the most secure and manageable solution?

Medium
16

An application running on EC2 needs to access DynamoDB tables. What is the most secure way to provide these permissions?

Medium
17

Refer to the exhibit. This S3 bucket policy is applied to a bucket named 'marketing-data'. What is the effect of this policy regarding access to the objects in the bucket?

Hard
18

An organization is migrating to AWS and needs to enforce security guardrails across multiple accounts. Which TWO actions should the security team perform to ensure compliance? (Select TWO)

Hard
19

Refer to the exhibit. A developer is attempting to upload a file to 'my-secure-bucket' using the S3 console but receives an Access Denied error. The developer is not specifying any encryption settings during the upload. Based on the provided IAM policy, what is the reason for the failure?

Hard
20

An application running on an Amazon EC2 instance needs to access files in an Amazon S3 bucket. What is the most secure way to provide the application with the necessary credentials?

Easy
21

A security team wants to identify which IAM roles in their AWS account have been granted permissions that allow access from external AWS accounts or public entities. Which AWS service should they use to automate this audit?

Easy

Frequently asked questions

What does the Identity and Access Management domain cover on the SCS-C03 exam?
Identity and Access Management questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 21 Identity and Access Management questions in the SCS-C03 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Identity and Access Management questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
aws-scs-c03 AWS-SCS-C03 identity and access management Practice Questions